Files
finit/test/lib/sysroot.mk
T
Joachim Wiberg f0d7257374 Fix #492: add per-service directories, systemd RuntimeDirectory style
A service that drops privileges cannot create its own PID file in
/run, root owns it.  Finit can create the file with pidfile-create,
but the daemon still cannot touch it to confirm a SIGHUP.

Five new settings, block format only: runtime-dir, state-dir,
cache-dir, logs-dir, and config-dir.  The value is a directory name,
resolved under /run, /var/lib, /var/cache, /var/log, and /etc,
respectively.  The directory is created before the service starts,
mode 0755 owned by user/group, and the full path is exported to the
process as RUNTIME_DIRECTORY, STATE_DIRECTORY, CACHE_DIRECTORY,
LOGS_DIRECTORY, and CONFIGURATION_DIRECTORY.  Mode and ownership are
asserted at creation only, a daemon may tighten them afterwards.

The runtime directory is removed when the unit stops, after any
exec-stop-post script, like systemd with RuntimeDirectoryPreserve=no.
A completed run/task counts as stopped unless remain-after-exit keeps
it up.  The other four persist across restarts.

These are the first settings with no legacy token: they are validated
by service_set_dir() and stored on the svc that service_register()
now returns.  systemd accepts a list of directories per setting; this
is a single name for now, widening later is compatible since
libconfuse accepts a bare value for a list option.

The test sysroot gains libnss_files.so.2, which ldd cannot see, glibc
dlopen()s it.  Without it getpwnam() fails inside the chroot, so
user/group settings never resolved and directory ownership could not
be tested.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-07-30 15:23:37 +02:00

90 lines
3.4 KiB
Makefile

# Root file system for test environment.
#
# Copyright (c) 2021 Jacques de Laval <jacques@de-laval.se>
#
# Permission is hereby granted, free of charge, to any person obtaining a copy
# of this software and associated documentation files (the "Software"), to deal
# in the Software without restriction, including without limitation the rights
# to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
# copies of the Software, and to permit persons to whom the Software is
# furnished to do so, subject to the following conditions:
#
# The above copyright notice and this permission notice shall be included in
# all copies or substantial portions of the Software.
#
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
# OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
# THE SOFTWARE.
srcdir ?= ../
SKEL ?= $(srcdir)/skel
DEST ?= ../sysroot
CACHE ?= ~/.cache
ARCH ?= x86_64
FINITBIN ?= ./sbin/finit
BBVER ?= 1_35_0
BBBIN = busybox-$(ARCH)
BBHOME ?= https://github.com/troglobit/busybox-builder/releases/download
BBURL ?= $(BBHOME)/$(BBVER)/$(BBBIN)
# glibc dlopen()s NSS modules at runtime, so ldd does not list them, but
# without libnss_files getpwnam() cannot resolve users inside the chroot
_libs_nss = $(firstword $(wildcard /lib/$(ARCH)-linux-gnu/libnss_files.so.2 \
/usr/lib/$(ARCH)-linux-gnu/libnss_files.so.2 \
/lib64/libnss_files.so.2 /lib/libnss_files.so.2))
_libs_src = $(shell ldd $(FINITBIN) | grep -Eo '/[^ ]+') $(_libs_nss)
libs = $(foreach path,$(_libs_src),$(abspath $(DEST))$(path))
all: $(libs) $(DEST)/bin/$(BBBIN)
@(cd $(DEST); \
for prg in `./bin/$(BBBIN) --list-full`; do \
case $$prg in \
usr/bin/* | usr/sbin/*) \
ln -sf ../../bin/$(BBBIN) $$prg;; \
bin/* | sbin/*) \
ln -sf ../bin/$(BBBIN) $$prg;; \
*) \
ln -sf bin/$(BBBIN) $$prg;; \
esac; \
done)
$(DEST)/bin/$(BBBIN).sha256:
@mkdir -p $(DEST)
@cp -a $(SKEL)/* $(DEST)/
@chmod -R u+w $(DEST)/
@find $(DEST) -name .empty -delete
$(DEST)/bin/$(BBBIN): $(DEST)/bin/$(BBBIN).sha256
@(cd $(dir $@); \
if ! sha256sum --status -c $(BBBIN).sha256 2>/dev/null; then \
if [ -d $(CACHE) ]; then \
echo "Cannot find $(BBBIN), checking $(CACHE) ..."; \
cd $(CACHE); \
cp -v $(DEST)/bin/$(BBBIN).sha256 .; \
if ! sha256sum --status -c $(BBBIN).sha256; then \
echo "No $(BBBIN), downloading $(BBURL) ..."; \
wget -O $(BBBIN) $(BBURL); \
else \
echo "Found valid $(BBBIN) in cache!"; \
fi; \
cp $(BBBIN) $@; \
cd $(dir $@); \
else \
echo "Cannot find $(BBBIN), downloading ..."; \
wget -O $@ $(BBURL); \
fi; \
sha256sum -c $(BBBIN).sha256 || (rm $@; false); \
fi)
@chmod +x $@
$(libs): $(DEST)/bin/$(BBBIN).sha256
mkdir -p $(dir $@)
cp $(patsubst $(abspath $(DEST))%,%,$@) $@